← Pricing / Starter
Starter - 99 EUR
A single automated, read-only scan of your public website. 15 passive HTTP/TLS checks. PDF summary emailed within 24 hours.
What the automated scan checks (honest scope)
- HTTPS redirect enforcement
- HSTS header (+ preload flag when present)
- Content-Security-Policy presence
- X-Frame-Options / CSP frame-ancestors
- X-Content-Type-Options (nosniff)
- Referrer-Policy
- Permissions-Policy
- Cookie flags (HttpOnly / Secure / SameSite) on Set-Cookie headers
- TLS version signals available at the edge
- Server / X-Powered-By banner leakage
- Mixed content in HTML
- Subresource Integrity on external scripts
- robots.txt presence
- .well-known/security.txt presence
- Basic technology fingerprint (CMS/library hints in HTML/headers)
Not included in Starter automated scan: open port scans, DNSSEC/SPF/DKIM/DMARC deep DNS, CVE databases, HaveIBeenPwned/breach lookups, subdomain enumeration, cloud bucket discovery, or authenticated testing. Those belong in Standard/Premium human engagements.
What you do NOT get
- Manual triage or engineer review
- Exploitation attempts
- Authenticated testing
- Remediation support
- NDA or written engagement letter
If you need any of the above, the Standard tier starts at 799 EUR and includes 8 hours of engineer review.
Order now - EUR 99
Card checkout via Stripe. Scan starts within 24 hours of payment clearing. PDF emailed to the address you use at checkout.
What happens next
- Stripe confirms payment (Apple Pay / Google Pay / card).
- Scoping email reaches you within 60 seconds.
- Reply with any authentication or scope notes (optional).
- Scan runs within 24 hours. PDF delivered to the email on your order.
Refund policy
If the scan cannot reach your domain (DNS misconfiguration, rate limit, geo-block), you get a full refund. If findings are disputed, we re-run the specific check at no charge. Once the PDF is delivered, the engagement is considered complete.